Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2005-3416

Published: 1 November 2005

phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings instead of arrays, which causes an array_merge function call to fail.

Priority

Unknown

Status

Package Release Status
phpbb2
Launchpad, Ubuntu, Debian
dapper
Released (2.0.18-2)
edgy
Released (2.0.18-2)
feisty
Released (2.0.18-2)
upstream Needs triage